binius_ip/sumcheck/verify.rs
1// Copyright 2025 Irreducible Inc.
2
3use binius_field::Field;
4
5use super::error::Error;
6use crate::{
7 channel::IPVerifierChannel,
8 sumcheck::{RoundCoeffs, RoundProof},
9};
10
11/// The reduced output of a sumcheck verification.
12///
13/// The [`verify`] function reduces a claim about the sum of a multivariate polynomial over the
14/// boolean hypercube to its evaluation at a challenge point.
15#[derive(Debug, Clone, PartialEq, Eq)]
16pub struct SumcheckOutput<F> {
17 /// The evaluation of the sumcheck multivariate at the challenge point.
18 pub eval: F,
19 /// The sequence of sumcheck challenges defining the evaluation point.
20 pub challenges: Vec<F>,
21}
22
23/// Verify a sumcheck protocol interaction.
24///
25/// The sumcheck verifier reduces a claim about the sum of a multivariate polynomial over the
26/// boolean hypercube to its evaluation at a challenge point.
27///
28/// ## Arguments
29///
30/// * `n_vars` - The number of variables in the multivariate polynomial
31/// * `degree` - The degree of the univariate polynomial in each round
32/// * `sum` - The claimed sum of the multivariate polynomial over the boolean hypercube
33/// * `channel` - The channel for receiving prover messages and sampling challenges
34///
35/// ## Returns
36///
37/// Returns a `Result` containing the `SumcheckOutput` with the reduced evaluation and challenge
38/// point, or an error if verification fails.
39pub fn verify<F, C>(
40 n_vars: usize,
41 degree: usize,
42 mut sum: C::Elem,
43 channel: &mut C,
44) -> Result<SumcheckOutput<C::Elem>, Error>
45where
46 F: Field,
47 C: IPVerifierChannel<F>,
48{
49 let mut challenges = Vec::with_capacity(n_vars);
50 for _round in 0..n_vars {
51 let round_proof = RoundProof(RoundCoeffs(channel.recv_many(degree)?));
52 let challenge = channel.sample();
53
54 let round_coeffs = round_proof.recover(sum);
55 sum = round_coeffs.evaluate(&challenge);
56 challenges.push(challenge);
57 }
58
59 Ok(SumcheckOutput {
60 eval: sum,
61 challenges,
62 })
63}